A tractor that never arrives, a fertilizer payment sent to the wrong account, or an order system that stops working can disrupt an agricultural business quickly.
A practical starting sequence
Give each check an owner and evidence. A completed checklist is useful only when it shows what was actually verified.
| Capability | Evidence to request | Suggested owner |
|---|---|---|
| Critical work and accounts | Priority workflows, account owners, administrator list, and acceptable outage times | Owner or operations lead |
| Payment and vendor access | Independent callback rule, vendor-access register, and removal procedure | Finance lead and IT provider |
| Recovery and outage readiness | Dated restore test, offline contacts, and a short response plan | IT provider and operations lead |
Why agriculture cybersecurity deserves attention
Agricultural businesses do not need a fully automated farm to have meaningful cyber risk. Business email, online banking, supplier portals, remote support, and shared records can all affect whether orders, deliveries, and payments continue.
The Food and Ag-ISAC has tracked ransomware affecting food and agriculture organizations, while government warnings have described scammers impersonating farm equipment businesses. Those reports do not predict what will happen to any individual farm or prove that a public signal is exploitable. They do show why ordinary business decisions deserve a short verification step.
This guide is for farms, agricultural retailers, grain businesses, cooperatives, and farm-service companies. Use it to decide what to ask your IT provider and what evidence is worth keeping.
1. Identify what must keep working
Start with business functions, not a list of software. Identify the systems behind receiving grain, scheduling deliveries, purchasing inputs, issuing invoices, paying suppliers, and accessing field or customer records.
For each essential function, record its owner, support contact, acceptable outage time, and dependencies. Include cloud services, internet access, printers, equipment-vendor connections, and the people who know how the process works.
Ask operations staff about systems the office may overlook, such as scale software, a service technician’s remote-access tool, or a tablet used for application records.
2. Protect email, banking, and administrator accounts
Give each person an individual account. Use unique passwords in a password manager, require multifactor authentication where supported, and separate administrator access from everyday email use.
For compatible services, consider phishing-resistant sign-in methods such as passkeys or security keys. Review recovery email addresses, phone numbers, and owners as well as the sign-in policy. An old employee’s recovery method can undermine an otherwise strong account.
Ask your provider for the account list, enforced authentication settings, administrator assignments, and current recovery contacts. “Everyone is enrolled in MFA” is not the same as showing that required sign-ins enforce it.
3. Verify equipment purchases and payment changes independently
A familiar dealership name, professional invoice, or convincing website should not authorize a transfer by itself. Independently contact the real dealership and confirm the salesperson, equipment, stock or serial number, location, and payment recipient.
For supplier bank-detail changes, call a previously verified contact using the number already in your records. Do not use a replacement number supplied in the change request. Require a second approval for new payees, changed bank details, and larger transactions.
Keep a short record of who verified the request, which trusted contact method they used, and who approved it. A reply in the same email thread is not independent verification.
4. Check what your business exposes to the internet
Review business domains, websites, email authentication, and public-facing remote-access services. Ask who owns each service, whether it is still required, and how it is maintained.
For email, have a qualified administrator review SPF, DKIM, and DMARC. Identify legitimate sending services before tightening enforcement so invoices and customer messages continue to arrive. DMARC can help reduce unauthorized use of your exact domain; it does not stop lookalike domains, compromised legitimate mailboxes, or every impersonation attempt.
A visible login page or old subdomain is an observation, not proof of a vulnerability or compromise. Give each finding an owner and a next question.
5. Make vendor remote access deliberate and accountable
Equipment dealers, software providers, and IT companies may need remote access. Document how they connect, what they can reach, who sponsors the relationship, and how access is removed.
Use named accounts, the narrowest necessary permissions, strong authentication where supported, and logging. Disable unnecessary access and use time-limited access where practical. Ask: “If we ended this vendor relationship today, could we remove every access path?” Include remote-support software and vendor cloud accounts in the answer.
Coordinate changes affecting equipment with the qualified vendor. Security work should not create an unsafe operating condition.
6. Separate office systems from equipment controls
Operational technology includes systems that monitor or control irrigation, grain drying, refrigeration, environmental conditions, and other physical processes.
Have your IT provider and equipment specialist confirm how those systems connect to office devices, guest Wi-Fi, and remote support. Restrict communication to what the operation needs. Giving networks different names does not establish that traffic between them is controlled.
Protect configuration backups and document a safe operating response if connectivity is lost. Avoid unplanned scanning, software installation, or firmware changes on production controls.
7. Fix the most consequential software weaknesses first
Keep routine updates moving, but prioritize issues according to exposure, exploitation evidence, and operational consequence. An exposed remote-access appliance may warrant faster action than a less consequential issue on an isolated device.
Ask your provider to identify affected products and versions, confirm vendor guidance, and assign a completion date. Where an operational system cannot be patched immediately, agree on temporary protections and schedule the permanent correction.
Request a remediation list showing the affected asset, reason for priority, responsible person, temporary protection if needed, and proof that the correction was completed.
8. Demonstrate recovery before you depend on it
A successful backup notification does not establish that the business can resume work. Choose one important workflow, such as accessing customer orders or producing invoices, and test recovery in an appropriate isolated environment.
Have the person who uses the records confirm that restored data is usable. Record the elapsed time, missing items, application settings, licensing dependencies, and the people needed to bring the workflow back.
Protect backup administration separately and maintain copies that compromised production accounts cannot readily alter or delete. For cloud applications, confirm retention, export, and recovery responsibilities instead of assuming the subscription covers every loss.
9. Train people on the requests they actually receive
Use scenarios that match agricultural work: a changed fertilizer invoice, an equipment deposit, a shared agronomy document, or an urgent request to reset a supplier-portal password.
Teach staff to verify unexpected requests through known channels and report mistakes quickly. Include suspicious texts and phone calls, not just email. A website asking someone to paste commands into a computer to complete a verification check should trigger a stop-and-report response.
Include seasonal staff, family members who help with administration, and employees using phones in the field. Make reporting simple and supportive.
10. Rehearse a busy-day outage
Run a short discussion with this scenario: “Email and the order system are unavailable at 7 a.m., and deliveries are already arriving.” Decide who contacts IT, who can authorize containment, how employees communicate, and which activities can continue safely.
Keep essential contacts and approved fallback procedures outside the affected systems. If a payment may have gone to a fraudster, contact the financial institution immediately, preserve the messages and transaction details, and involve your response provider promptly when a technology compromise is suspected.
Request a one-page response plan, an offline contact list, and the actions identified during the exercise.
Where should an agricultural business start?
This week, review critical accounts and payment-change procedures. Over the next two weeks, review public exposure and vendor access. Within 30 days, test one recovery workflow and rehearse an outage. Before each busy season, review staffing, equipment connections, and open findings.
Do not buy another platform simply because a checklist is long. First determine which safeguards are missing, which existing tools can provide them, and which results you can verify. Public exposure can identify questions; it cannot prove internal security.
Common questions about agriculture cybersecurity
Do small farms need cybersecurity if they use little automation?
Yes. Email, online banking, equipment purchases, and supplier accounts create exposure even without connected machinery. Start with account protection, payment verification, and recovery of essential records.
Is antivirus enough to protect an agricultural business?
No. Endpoint protection is one safeguard. It does not independently verify an equipment seller, approve a bank-detail change, remove an old vendor account, or demonstrate that backups restore successfully.
Can an external review confirm that our farm is secure?
No. A public review identifies signals and questions worth investigating. Internal account settings, backup effectiveness, staff behavior, and equipment-control security require different evidence and agreed assessment methods.
Related resources
Turn the checklist into verified next steps.
The free Zero-Access Business Exposure Review checks public signals around your domains, email, websites, and internet-facing services. The $1,995 Business Security Baseline goes further by reviewing agreed internal safeguards and available evidence for businesses with up to 25 employees.
